Effective Date: 10 July 2026
This Terms of Service Agreement ("Agreement") is a legally binding contract between Nuworks Ltd, a company incorporated and registered in England, trading as BrokerCentral ("BrokerCentral", "Provider", "we", "our", or "us"), and the individual or entity ("Customer", "you", or "your") that accesses, installs, or uses the BrokerCentral software and related services (the "Services").
The BrokerCentral Services are offered to the Customer subject to its acceptance of these BrokerCentral Terms of Service (the “Terms”). By accessing, installing, or using the BrokerCentral Services, or by otherwise indicating assent to these Terms, the Customer enters into a legally binding contract with BrokerCentral.
IF YOU ARE ENTERING INTO THESE TERMS ON BEHALF OF AN ENTITY, SUCH AS YOUR EMPLOYER OR THE COMPANY YOU WORK FOR, YOU REPRESENT AND WARRANT THAT YOU HAVE THE LEGAL AUTHORITY TO BIND SUCH ENTITY. IN SUCH A CASE, THE TERMS "YOU," "YOUR," "CUSTOMER," OR ANY SIMILAR CAPITALISED TERM HEREIN WILL REFER TO SUCH ENTITY.
These Terms constitute a contract governing the Customer’s use of the BrokerCentral Services and include the following documents expressly incorporated by reference:
BY REGISTERING FOR, PURCHASING ACCESS TO, ACCESSING, AND/OR USING THE BROKERCENTRAL SERVICES OR OTHERWISE INDICATING ASSENT, YOU REPRESENT AND WARRANT THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THESE TERMS. IF YOU DO NOT AGREE TO BE BOUND BY THESE TERMS, DO NOT ACCESS OR USE THE BROKERCENTRAL SERVICES.
ANY DISPUTE ARISING OUT OF OR IN CONNECTION WITH THESE TERMS OR THE BROKERCENTRAL SERVICES SHALL BE HANDLED IN ACCORDANCE WITH THE DISPUTE RESOLUTION PROVISIONS SET OUT IN SECTION 17 BELOW AND THE GOVERNING LAW AND JURISDICTION PROVISIONS SET OUT IN SECTION 18.6 BELOW.
THE PARTIES WILL FIRST SEEK TO RESOLVE DISPUTES THROUGH GOOD FAITH NEGOTIATIONS BETWEEN AUTHORISED REPRESENTATIVES. IF A DISPUTE CANNOT BE RESOLVED THROUGH THOSE NEGOTIATIONS, THE COURTS OF ENGLAND AND WALES SHALL HAVE EXCLUSIVE JURISDICTION, SUBJECT TO ANY RIGHTS TO SEEK INTERIM, INJUNCTIVE, EQUITABLE, DEBT RECOVERY, OR INTELLECTUAL PROPERTY-RELATED RELIEF WHERE PERMITTED UNDER THESE TERMS.
(a) any information disclosed (whether in writing, orally, or otherwise) by the Customer to the Provider that is marked as “confidential”, described as “confidential”, or should have been understood by the Provider at the time of disclosure to be confidential;
(b) the financial terms and conditions of this Agreement;
(c) the Customer Materials; and
(d) any other information that a reasonable person or entity would consider confidential in nature.
(a) uploaded to, stored on, processed using, or transmitted via the Platform by or on behalf of the Customer, or by any person, application, or automated system using the Customer's account; and
(b) otherwise provided by the Customer to the Provider for the purposes of or in connection with this Agreement.
(a) the UK General Data Protection Regulation (“UK GDPR”);
(b) the Data Protection Act 2018;
(c) the Privacy and Electronic Communications Regulations 2003 (“PECR”);
(d) the Data (Use and Access) Act 2025 (“DUAA 2025”);
(e) any legislation by which the foregoing is amended, replaced, supplemented or re-enacted; and
(f) any binding guidance, statutory codes, or regulatory requirements issued by the Information Commissioner’s Office (“ICO”) or other competent supervisory authority.
(a) an act or omission of the Customer, or an act or omission of one of the Customer's employees, officers, agents, suppliers, or subcontractors; or
(b) an incompatibility between the Platform and any system, application, program, or software not specified as compatible in the Order Form.
In this Agreement, a reference to a statute or statutory provision includes a reference to:
(a) that statute or statutory provision as amended, replaced, supplemented or re-enacted from time to time; and
(b) any subordinate legislation made under that statute or statutory provision.
The Clause headings do not affect the interpretation of this Agreement.
The ejusdem generis rule is not intended to be used in the interpretation of this Agreement.
Unless otherwise agreed in writing, this Agreement shall automatically renew for successive periods equal to the initial Subscription Term unless either party gives written notice of non-renewal at least:
(a) 60 days prior to the Term Expiry Date for Subscriptions with a term longer than one month; or
(b) 7 days prior to the Term Expiry Date for rolling monthly Subscriptions.
Each renewal shall be subject to the Fees, Subscription entitlements, service terms, and policies applicable immediately prior to renewal, subject to:
(a) any annual CPI-based Fee adjustment permitted under Clause 7.5;
(b) any pricing, usage, entitlement, or renewal changes expressly stated in the applicable Order Form;
(c) any additional Fees for Add-On Features, New Functionality, Additional Projects, increased usage, additional users, upgraded entitlements, support services, professional services, or premium services ordered, enabled, agreed to, or used by the Customer; and
(d) any changes to incorporated policies or service documents made in accordance with Clause 18.7.
The Provider shall give the Customer reasonable prior notice of any material change to Fees applicable on renewal, except where the change arises from an annual CPI-based adjustment under Clause 7.5, an existing Order Form mechanism, or additional Fees for services, functionality, usage, or entitlements ordered, enabled, agreed to, or used by the Customer.
If the Customer does not agree to a notified material change to Fees applicable on renewal, the Customer may elect not to renew the affected Services by giving notice in accordance with this Clause 2.4.
Continued access to or use of the Services following renewal constitutes acceptance of the renewed Fees and applicable terms.
Except where required by law or expressly permitted in this Agreement:
(a) The Customer may not sub-license, rent, or assign its right to use the Platform, except as provided in Clauses 3.8 and 3.9.
(b) The Customer must not frame, re-publish, or redistribute any part of the Platform.
(c) The Customer must not alter, adapt, reverse engineer, decompile, disassemble, or modify the Platform.
The Customer must comply with all applicable sanctions, export control, trade compliance, and import laws relating to its access to and use of the Platform and Services. The Provider may suspend, restrict, or terminate access to the Services where reasonably necessary to comply with applicable sanctions, export control laws, trade restrictions, or regulatory requirements, or where continued provision of the Services may expose the Provider to legal, regulatory, or reputational risk.
The Provider may update, modify, enhance, replace, suspend, or discontinue parts of the Platform from time to time, including to improve functionality, maintain security, comply with applicable law, or reflect changes to the Services.
Where reasonably practicable, the Provider will provide advance notice of material changes that are likely to materially adversely affect the Customer’s use of the Platform.
Nothing in this Clause prevents the Provider from making immediate changes where necessary for security, legal, operational, or technical reasons.
The Provider will use commercially reasonable efforts to avoid materially reducing the core functionality of the Platform during the applicable Subscription Term.
The Customer must:
(a) Use all reasonable endeavours to ensure that unauthorised persons do not access the Platform using the Customer’s credentials.
(b) Notify the Provider immediately in case of unauthorised access, data breaches, or credential misuse.
(c) Be responsible for ensuring the security of user credentials and account access, including by implementing reasonable account security practices. The Customer is responsible for enabling available multi-factor authentication (MFA) where appropriate, particularly for administrative or privileged accounts. The Provider is not liable for breaches, unauthorised access, or credential misuse caused by weak, shared, compromised, or inadequately protected Customer credentials, or by the Customer’s failure to implement reasonable account security controls.
The Provider shall:
(a) maintain appropriate technical and organisational measures designed to protect Customer Materials and Personal Data against unauthorised or unlawful access, disclosure, alteration, loss, or destruction, as further described in the Data Processing Agreement and Annex 1 (Technical and Organisational Measures). Such measures shall be appropriate to the nature of the Services and the risks presented by the processing activities undertaken by the Provider.
The Customer may permit authorised third parties to access the Platform only where:
The Customer remains fully responsible and liable for all acts, omissions, and use of the Platform by any third party accessing the Platform through the Customer’s account or under the Customer’s authority.
The Customer must not permit the sharing of user accounts, shared login credentials, or generic access credentials except where expressly authorised by the Provider in writing for a specific operational purpose.
The Customer may permit approved Affiliates or authorised third parties to access and use the Platform within the scope expressly authorised in the applicable Order Form, provided that:
(a) the Provider gives prior written consent, such consent not to be unreasonably withheld or delayed;
(b) any approved sub-licence or third-party access is limited to the Customer’s internal business operations and permitted use of the Platform;
(c) the Customer remains fully responsible and liable for all acts, omissions, access, use, processing activities, and breaches by any sub-licensee, Affiliate, contractor, consultant, integration provider, managed service provider, or other third party accessing the Platform through or on behalf of the Customer;
(d) the Customer shall ensure that all sub-licensees and authorised third parties are bound by written obligations relating to confidentiality, security, acceptable use, data protection, and access controls that are no less protective than those contained in this Agreement, the Acceptable Use Policy, and the Data Processing Agreement;
(e) all users accessing the Platform under any sub-licence must use individual named user accounts and unique authentication credentials, and the Customer shall ensure appropriate role-based access controls and prompt removal of unnecessary access rights;
(f) the Customer shall ensure that any processing of Personal Data by a sub-licensee or authorised third party complies with applicable Data Protection Laws and does not cause the Provider to breach applicable law or regulatory obligations;
(g) the Provider may suspend, restrict, or terminate any approved sub-licensed access where reasonably necessary for security, operational, legal, regulatory, or compliance reasons; and
(h) any additional Fees applicable to approved sub-licensing arrangements shall be reflected in the applicable Order Form.
The Customer must not permit shared accounts, generic credentials, uncontrolled onward access, or any use of the Platform that would compete with, replicate, resell, or commercially exploit the Platform except as expressly authorised in writing by the Provider.
Certain aspects of the Platform include artificial intelligence or machine learning capabilities (“AI Functionality”). AI Functionality forms part of the Services and provides AI-assisted workflow support within the Platform, including functionality designed to assist with drafting, summarisation, recommendations, operational workflows, and other user-support activities made available within the Services from time to time.
Unless expressly agreed otherwise in writing by BrokerCentral, AI Functionality may be made available within normal Platform workflows and is not a separately disableable service or optional add-on at Customer level. The Customer is not required to rely on AI-generated outputs, and Authorised Users may choose not to accept or use AI-generated suggestions, recommendations, drafts, summaries, or other outputs.
The Customer acknowledges that AI-generated outputs may not always be accurate, complete, reliable, current, legally compliant, non-discriminatory, or suitable for the Customer’s intended use. The Customer and its Authorised Users are responsible for reviewing, verifying, and validating all AI-generated outputs before accepting, applying, sending, publishing, recording, or otherwise relying on them.
Unless expressly agreed otherwise in writing by BrokerCentral, AI Functionality is provided solely as a decision-support tool and is not intended to operate as a fully automated decision-making system. AI-generated outputs must not be used as the sole basis for regulated, legal, financial, insurance, employment, customer-facing, compliance, or similarly significant decisions. The Customer must ensure that appropriately qualified personnel apply meaningful human review, verification, and professional judgment before using or relying on AI-generated outputs in any such context.
The Customer shall ensure that AI Functionality is used in a lawful, fair, transparent, and accountable manner consistent with applicable Data Protection Laws and any applicable laws, regulations, or regulatory guidance relating to automated processing, profiling, artificial intelligence, discrimination, consumer protection, insurance, financial services, PECR, cookies, similar tracking technologies, electronic marketing communications, or electronic communications.
The Customer must not use AI Functionality:
The Customer acknowledges that:
The Provider may implement operational, technical, security, monitoring, filtering, rate-limiting, logging, review, or governance controls relating to AI Functionality where reasonably necessary to:
The Customer shall ensure that appropriately qualified personnel exercise meaningful human review and oversight over any decisions, actions, recommendations, or outputs generated using AI Functionality where such decisions may:
The Customer remains solely responsible for:
The Provider does not use Customer Data, Customer Personal Data, prompts or outputs to train public or shared AI models, and contractually restricts relevant AI providers from doing so, unless expressly agreed in writing.
Where AI Functionality relies on third-party AI service providers, the Customer acknowledges that relevant input and output data may be processed by such providers in accordance with applicable data protection laws, PECR where applicable, and the Provider’s agreements with those providers.
The Provider reserves the right to suspend, restrict, modify, or withdraw AI Functionality where reasonably necessary to address legal, regulatory, ethical, security, operational, privacy, Tracking Technology, electronic communications, or third-party provider requirements.
The Provider may sub-contract the provision of Support Services and other operational services without obtaining prior consent from the Customer, provided that:
The Customer grants the Provider, during the Subscription, a non-exclusive, worldwide, royalty-free licence to host, store, process, transmit, copy, and otherwise use the Customer Materials solely to the extent necessary to:
Nothing in this Agreement grants the Provider any right to:
To the extent the Provider processes Personal Data contained within Customer Materials on behalf of the Customer, such processing shall be governed exclusively by the Data Processing Agreement.
(a) Breach any applicable laws, regulations, or legally binding codes;
(b) Infringe any third party’s Intellectual Property Rights or other legal rights; or
(c) Give rise to any claim, legal action, or liability against the Provider, the Customer, or any third party.
(a) Remove, modify, or restrict access to the relevant Customer Materials; and/or
(b) Suspend some or all of the Services and/or the Customer’s access to the Platform while investigating the matter.
(a) The Platform, including any customisations, modifications, or enhancements made by or for the Provider;
(b) The Services, including any support, updates, or additional features;
(c) The Documentation; and
(d) Any Additional Projects developed or delivered by the Provider.
If the Customer fails to pay any undisputed amount due under this Agreement by the applicable due date, the Provider may:
(a) charge interest on the overdue amount at the statutory rate applicable under the Late Payment of Commercial Debts (Interest) Act 1998, accruing daily from the due date until payment is made in full;
(b) recover fixed compensation, reasonable debt recovery costs, administrative costs, legal costs, and collection costs to the extent permitted under applicable law;
(c) suspend or restrict access to the Platform and Services in accordance with Clause 7.6 until all overdue undisputed amounts are paid; and
(d) charge reasonable reactivation, administration, storage, recovery, or restoration fees associated with restoring suspended Services.
The Provider’s rights under this Clause are without prejudice to any other rights or remedies available under this Agreement or applicable law.
Where the Late Payment of Commercial Debts (Interest) Act 1998 does not apply, the Provider may charge interest on overdue undisputed amounts at a rate of eight percent (8%) per annum above the Bank of England base rate, accruing daily from the due date until payment is made in full.
Unless otherwise stated in the applicable Order Form, the Provider may increase recurring Subscription Fees once in each twelve (12) month period by an amount not exceeding the percentage increase in the UK Consumer Prices Index over the relevant period.
The Provider shall give the Customer reasonable written notice of any annual CPI-based Fee increase before it takes effect.
Except for annual CPI-based increases permitted under this Clause 7.5, increases expressly stated in the applicable Order Form, or increases otherwise agreed in writing by the Customer, the Provider shall not increase recurring Subscription Fees during the then-current Subscription Term.
The Provider may charge additional Fees for Add-On Features, New Functionality, Additional Projects, increased usage, additional users, upgraded entitlements, support services, professional services, premium services, bespoke modifications, customer-requested enhancements, restoration requests, migration assistance, or other chargeable services where such items are ordered, enabled, agreed to, requested, or used by the Customer in accordance with this Agreement, the applicable Order Form, the purchase process, or other written agreement.
Nothing in this Clause prevents the Provider from charging Fees or Charges already contemplated by this Agreement, including Charges for Additional Projects, Add-On Features, restoration work, migration assistance, overdue payment recovery, or usage exceeding the Customer’s agreed Subscription plan.
If any undisputed payment remains overdue for more than fifteen (15) days, the Provider may, upon written notice and without liability:
During any suspension period, the Provider shall retain Customer Materials securely in accordance with the Data Processing Agreement and applicable law.
The Provider shall not permanently delete Customer Materials solely due to non-payment except:
Subject to payment of reasonable applicable fees and compliance with law, the Customer may request export of its Customer Materials during the applicable retention period in a commonly used machine-readable format.
The Customer’s Subscription may include usage allowances, limits, entitlements, or assumptions relating to storage, data volume, document volume, records, attachments, communications, emails, API calls, integrations, automations, AI Functionality, users, workflows, transactions, support usage, or other usage metrics, as specified in the applicable Order Form, pricing schedule, plan description, Documentation, or other written notice provided by the Provider.
If the Customer exceeds any applicable usage allowance, limit, entitlement, or reasonable usage assumption, the Provider may do one or more of the following:
(a) notify the Customer of the excess usage;
(b) require the Customer to reduce usage to within the applicable allowance or entitlement;
(c) charge additional Fees or Charges for the excess usage;
(d) require the Customer to move to an appropriate Subscription plan, usage tier, or add-on package;
(e) restrict or suspend non-essential functionality where reasonably necessary to manage infrastructure, security, operational, cost, or service performance risks; and/or
(f) agree revised commercial terms with the Customer.
Where the Customer’s use of the Platform exceeds any storage allowance specified in the applicable Order Form, pricing schedule, plan description, Documentation, or written notice, the Provider may charge excess storage Fees at the rate specified in the applicable Order Form or, where no rate is specified, at the Provider’s then-current standard excess storage rates.
Storage usage may include Customer Materials, Customer Data, uploaded files, documents, attachments, records, communications, generated outputs, and other materials stored within the production environment of the Platform by or on behalf of the Customer.
For clarity, routine backup copies, disaster recovery copies, and operational redundancy copies created by the Provider for its own resilience purposes shall not be double-counted as separate Customer storage usage, unless the Customer requests extended retention, restoration, bespoke archiving, historical retrieval, or other storage-related services outside the standard Subscription.
The Customer must use the Services in a fair, reasonable, and proportionate manner consistent with the nature of its Subscription, the intended use of the Platform, and the Provider’s operational, infrastructure, security, support, and cost assumptions.
The Provider may apply fair usage controls where the Customer’s use materially exceeds normal or reasonable usage patterns, imposes disproportionate storage, infrastructure, support, security, AI, messaging, API, backup, bandwidth, processing, or operational costs, or risks degrading the Services for the Provider, the Customer, or other customers.
Where reasonably practicable, the Provider will notify the Customer before applying material excess usage charges or requiring a move to a higher Subscription plan. However, the Provider may take immediate action without prior notice where reasonably necessary to protect the security, availability, integrity, performance, or lawful operation of the Services.
Unless otherwise stated in the applicable Order Form, excess usage Fees and Charges may be invoiced monthly in arrears and shall be payable in accordance with Clause 7.1.
Any delay or failure by the Provider to monitor, notify, restrict, suspend, or charge for excess usage shall not prevent the Provider from doing so later, nor shall it constitute a waiver of the Provider’s rights under this Agreement.
The Customer is responsible for monitoring its use of the Services and ensuring that its use remains within any applicable usage allowances, limits, entitlements, fair usage requirements, or agreed Subscription terms.
The Customer warrants that:
(a) It has the legal right and authority to enter into this Agreement and use the Platform in accordance with the Permitted Purpose.
(b) It is solely responsible for ensuring compliance with financial services legislation and regulations applicable to its business.
The Provider warrants that:
(a) It has the legal right and authority to enter into and perform its obligations under this Agreement.
(b) It will provide the Platform and Support Services with reasonable care and skill.
(c) The Platform will substantially perform as described in the Documentation, subject to any Upgrades.
(d) The Platform will be hosted in accordance with commitments set out in Schedule 1.
(e) The Platform (excluding Customer Materials) does not infringe any third-party Intellectual Property Rights.
The Customer acknowledges and agrees that:
(a) except as expressly set out in this Agreement, the Platform and Services are provided on an “as available” basis;
(b) while the Provider will use commercially reasonable efforts to maintain the availability, security, and functionality of the Platform in accordance with this Agreement and Schedule 1, the Provider does not warrant that the Platform will be uninterrupted, error-free, or completely free from Defects;
(c) the Platform may not be compatible with all third-party applications, systems, integrations, or software unless expressly stated in the applicable Order Form or Documentation;
(d) the Provider is not responsible for issues, failures, delays, vulnerabilities, or disruptions arising from:
(i) third-party integrations, applications, or services not controlled by the Provider;
(ii) Customer systems, infrastructure, internet connectivity, or configurations;
(iii) Customer misuse, unauthorised modifications, or use outside the Permitted Purpose; or
(iv) Beta Services, evaluation features, or third-party software made available on a non-production basis; and
(a) except to the extent prohibited by applicable law, all warranties, representations, conditions, and other terms not expressly set out in this Agreement are excluded to the fullest extent permitted by law.
(a) non-conformities, interruptions, or issues arising from Customer modifications, misuse, negligence, unauthorised access, or use of the Platform contrary to this Agreement or the Documentation;
(b) downtime, latency, interruptions, or failures caused by internet service providers, telecommunications networks, hosting providers, cloud infrastructure providers, or other third-party dependencies outside the Provider’s reasonable control;
(c) issues arising from third-party integrations, applications, APIs, or software not supplied or controlled by the Provider; or
(d) the Customer’s business operations, regulatory obligations, financial transactions, underwriting decisions, compliance activities, or operational decisions made using the Platform or AI Functionality.
(a) If a third party claims that the Platform infringes its Intellectual Property Rights, the Provider will, at its discretion:
(a) The Provider will have no obligation under Clause 8.5 if the claim results from:
The Customer shall indemnify, defend, and hold harmless the Provider, its Affiliates, officers, directors, employees, and agents from and against any liabilities, damages, losses, costs, and expenses (including legal fees) arising out of:
(a) The Customer’s breach of Clause 5.3 (Intellectual Property Rights of Customer Materials) or any other clause in this Agreement;
(b) The Customer’s misuse of the Platform, including violations of statutory, regulatory, or contractual obligations;
(c) Any third-party claims arising from the Customer’s data, including privacy violations, intellectual property disputes, or unauthorised data usage;
(d) Security breaches, data loss, or unauthorised access resulting from the Customer’s failure to maintain adequate security measures for its credentials, data, or systems;
(e) Any claims arising from third-party software, integrations, or applications not provided by the Provider and used by the Customer, where such claims result from incompatibility, security risks, or unauthorised modifications made to the Platform.
(f) any claims, penalties, fines, losses, damages, liabilities, costs, or expenses arising from the Customer’s breach of applicable Data Protection Laws, the Data Processing Agreement, unlawful processing instructions, failure to provide required privacy notices, failure to obtain required consents or lawful bases, or other acts or omissions for which the Customer is responsible under the Data Processing Agreement.
The Provider shall indemnify, defend, and hold harmless the Customer against any third-party claim arising out of a breach of Clause 8.2(e) (Intellectual Property Rights infringement), subject to the following conditions:
(a) The Customer must provide prompt written notice of any claim;
(b) The Customer must cooperate reasonably in the defense of the claim, at the Provider’s expense;
(c) The Provider has sole authority to defend or settle the claim.
In response to such a claim, the Provider may, at its discretion:
(i) Procure the right for the Customer to continue using the Platform;
(ii) Modify or replace the Platform to avoid infringement; or
(iii) If neither option (i) nor (ii) is commercially reasonable or feasible, terminate this Agreement and provide a pro-rata refund of Subscription Fees already paid for the unused period of the Subscription Term.
The Provider will not be liable for any claims arising from:
(a) Customer modifications to the Platform, including customisations, alterations, or third-party integrations added without the Provider’s prior written consent;
(b) Customer use of the Platform contrary to instructions or outside the scope of permitted use;
(c) Customer’s continued use of the Platform after an infringement notice;
(d) Security breaches, hacking, or unauthorised access caused by Customer negligence, lack of security controls, or failure to implement recommended updates;
(e) Third-party software, applications, or integrations that are not provided or maintained by the Provider, even if they interoperate with the Platform;
(f) Any claim based on the combination of the Platform with other software or services, where such combination causes infringement, malfunction, or security vulnerabilities.
(a) The Customer acknowledges that third-party integrations, applications not provided by the Provider, and external APIs may introduce security risks, data loss, or service disruptions, and that the Provider is not responsible for any resulting liabilities.
(b) The Customer is responsible for assessing the security, compliance, and reliability of any third-party integration before enabling it for use with the Platform.
(c) The Provider may, at its discretion, suspend or disable third-party integrations that pose a security or legal risk to the Platform, Services, or other Customers.
Except to the extent prohibited by applicable law, all indemnities under this Agreement shall be subject to the limitations and exclusions of liability set out in Clause 10.
Nothing in this Agreement shall:
(a) Limit or exclude a party's liability for death or personal injury caused by negligence;
(b) Limit or exclude a party's liability for fraud or fraudulent misrepresentation;
(c) Limit liability in a manner that is not permitted under applicable law; or
(d) Exclude liability that cannot legally be excluded.
(a) Subject to Clauses 10.1 and 10.3(b), each party’s aggregate liability arising out of or in connection with this Agreement, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall not exceed the total Charges and Fees paid or payable by the Customer under this Agreement during the six (6) months immediately preceding the event giving rise to the claim.
(b) The aggregate liability of either party arising from:
(a) The limitations in this Clause 10.3 apply collectively to all claims arising under or in connection with this Agreement and are not cumulative.
To the maximum extent permitted by law, under no circumstances will either party be liable to the other for:
(a) Third-party claims against the party for loss or damages;
(b) loss, corruption, destruction, alteration, unauthorised disclosure, or unavailability of the Customer’s records, data, or Customer Materials, except to the extent directly caused by the Provider’s failure to implement the security measures, backup procedures, or data protection obligations expressly required under this Agreement or the Data Processing Agreement, in which case the Provider’s liability shall remain subject to the limitations, exclusions, and liability caps set out in this Agreement.
(c) Loss of profit, revenue, goodwill, or anticipated savings (whether direct or indirect);
(d) Business interruption, lost opportunities, reputational damage, or increased costs;
(e) Any special, indirect, incidental, or consequential loss or damage, whether foreseeable or not, arising in connection with this Agreement.
For the avoidance of doubt, the Provider’s obligations relating to backup procedures, restoration efforts, Personal Data security, and Personal Data Breaches are governed by this Agreement, the Data Processing Agreement, and Schedule 1, and nothing in this Clause 10.4 excludes liability that cannot lawfully be excluded under applicable Data Protection Laws.
(a) Service Availability
The Provider does not guarantee uninterrupted or error-free service. The Customer acknowledges that occasional disruptions, maintenance, or third-party dependencies may impact service availability.
(b) Third-Party Applications & Integrations
The Provider shall not be liable for any damages, loss, or disruptions caused by:
(c) Third-Party Data Processing Risks
The Provider shall not be liable for any data breaches, unauthorised disclosures, or regulatory violations arising from the Customer's use of third-party data processing services, cloud storage solutions, or external applications.
(a) Security Responsibilities for Third-Party Applications
(i) The Customer is responsible for assessing the security, compliance, and reliability of any third-party integration before enabling it for use with the Platform.
(ii) The Provider does not guarantee that third-party integrations will comply with privacy laws, data protection regulations, or industry standards.
(iii) The Customer shall indemnify the Provider for any liability, claims, or regulatory fines arising from the Customer’s reliance on third-party applications or failure to implement appropriate security measures.
(e) Provider’s Right to Suspend Third-Party Integrations
The Provider may, at its sole discretion, suspend or disable any third-party integrations that pose a security, legal, or operational risk to the Platform, Services, or other Customers.
(a) No Guarantee of Accuracy
The Provider makes no warranties regarding the accuracy, reliability, suitability, completeness, legality, or availability of any AI-generated content, recommendations, analyses, insights, or outputs generated through AI-powered functionality within the Platform.
The Customer acknowledges that AI-generated outputs are based on statistical and machine-learning models and may contain errors, inaccuracies, biases, omissions, hallucinations, or incomplete information.
AI-generated outputs may be probabilistic in nature and may vary depending on prompts, contextual inputs, training limitations, third-party model behaviour, system configurations, and evolving technologies.
The Provider does not represent or warrant that AI-generated outputs will:
(a) Customer’s Responsibility for AI Use
(i) The Customer is solely responsible for reviewing, validating, verifying, and assessing all AI-generated outputs before relying on them for any business, financial, legal, insurance, underwriting, compliance, employment, operational, or regulatory purpose.
(i) The Customer must ensure that its use of AI Functionality and AI-generated outputs complies with:
(i) The Customer acknowledges that AI Functionality is intended to support, and not replace, human judgment unless expressly agreed otherwise in writing by the Provider.
(i) The Customer must ensure that appropriately qualified personnel exercise meaningful human oversight and review over any AI-assisted process, recommendation, output, or decision that may materially affect individuals, customers, transactions, underwriting decisions, claims handling, compliance activities, employment matters, or other legally or commercially significant outcomes.
(i) The Provider is not liable for any legal claims, regulatory penalties, enforcement action, business losses, reputational harm, or other liabilities resulting from:
(i) The Customer acknowledges that the Platform may display notices, prompts, warnings, confirmation steps, or similar controls reminding Authorised Users to check AI-generated outputs before use. Such notices are intended to support responsible use of AI Functionality and do not reduce the Customer’s responsibility to ensure that appropriately qualified personnel review, verify, and validate AI-generated outputs before relying on them.
(a) AI Training and Data Use
(i) The Provider does not use Customer Data, Customer Personal Data, prompts or outputs to train public or shared AI models, and contractually restricts relevant AI providers from doing so, unless expressly agreed in writing.
(i) If AI Functionality involves third-party AI service providers, the Customer acknowledges and agrees that relevant input and output data may be processed by such providers in accordance with:
(i) The Provider may use anonymised and aggregated operational telemetry, service analytics, security metrics, usage statistics, and performance data for:
(a) AI Restrictions
The Customer must not use AI Functionality:
(i) to generate deceptive, fraudulent, defamatory, unlawful, harmful, discriminatory, harassing, or misleading content;
(i) to conduct unlawful profiling, behavioural analysis, or automated risk scoring;
(i) to create fully automated decisions producing legal effects concerning an individual, or similarly significant effects, without appropriate lawful basis, safeguards, and meaningful human oversight;
(i) in any manner that violates applicable:
(i) to circumvent legal, regulatory, audit, compliance, or security controls;
(i) to process Special Category Data unlawfully; or
(i) in connection with any activity prohibited under the Acceptable Use Policy.
(a) Regulatory and Operational Controls
The Provider may implement monitoring, filtering, moderation, logging, rate limiting, suspension, restriction, governance, or operational controls relating to AI Functionality where reasonably necessary to:
(a) Right to Modify or Withdraw AI Functionality
The Provider reserves the right to suspend, restrict, modify, discontinue, or withdraw AI Functionality where reasonably necessary for legal, regulatory, ethical, operational, security, technical, or third-party dependency reasons.
The Provider shall not transfer, access, process, store, disclose, or otherwise make available Personal Data outside the United Kingdom or any jurisdiction subject to applicable international transfer restrictions unless such transfer complies with the Data Processing Agreement (DPA) and applicable Data Protection Laws.
Where restricted international transfers occur, the Provider shall implement lawful transfer mechanisms and appropriate technical, contractual, and organisational safeguards recognised under applicable Data Protection Laws, which may include:
The Provider may update, replace, supplement, or adopt alternative transfer mechanisms or safeguards where reasonably necessary to:
Where required under applicable Data Protection Laws, the Provider may conduct and maintain transfer risk assessments, vendor due diligence assessments, and supplementary technical and organisational safeguards relating to international transfers of Personal Data.
"Confidential Information" means all information disclosed by a party ("Disclosing Party") to the other party ("Receiving Party"), whether orally or in writing, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. Confidential Information includes but is not limited to:
The Receiving Party shall:
(a) Maintain the confidentiality of the Disclosing Party’s Confidential Information using at least the same degree of care that it uses to protect its own confidential information of a similar nature, but in no event less than reasonable care in accordance with industry standards.
(b) Not disclose the Confidential Information to any third party without the prior written consent of the Disclosing Party, except as permitted under Clause 12.3.
(c) Use the Confidential Information solely for the purpose of fulfilling its obligations under this Agreement.
Confidential Information may be disclosed only in the following circumstances:
(a) To employees, affiliates, officers, agents, insurers, or professional advisers who need to know such information to perform obligations under this Agreement, provided they are bound by similar confidentiality obligations.
(b) If required by law, regulation, court order, or regulatory authority, provided that the Receiving Party:
(a) If the Confidential Information:
(a) Upon termination of this Agreement, the Receiving Party shall:
(a) Retention in Routine Backups
(c) Compliance with Data Processing Agreement (DPA):
The Receiving Party’s obligations regarding the retention, deletion, or return of Personal Data shall be governed by the terms of the Data Processing Agreement (DPA). In the event of any conflict between this Agreement and the DPA regarding data handling, the terms of the DPA shall prevail.
The obligations of confidentiality under this Agreement shall survive termination or expiration of this Agreement for a period of five (5) years.
Notwithstanding the foregoing:
(a) any obligations relating to Personal Data shall survive for so long as required under applicable Data Protection Laws and the Data Processing Agreement; and
(b) any trade secrets, source code, algorithms, security procedures, encryption methods, non-public technical architecture, proprietary models, or other information constituting a trade secret under applicable law shall remain confidential for so long as such information retains its status as a trade secret under applicable law.
Either party may terminate this Agreement immediately by giving written notice if the other party:
(a) Commits a material breach of this Agreement and:
(i) The breach is not remediable; or
(ii) The breach is remediable but is not cured within 30 days of written notice.
(a) Persistently breaches any terms of this Agreement, even if no single breach is considered material.
(b) Becomes subject to insolvency, liquidation, or administration proceedings.
(a) 60 days before the end of the Subscription Term for Subscriptions longer than one month; or
(b) 7 days before the end of the Subscription Term for rolling monthly Subscriptions.
The Provider may suspend access to the Platform immediately (without terminating the Agreement) if:
(a) The Customer fails to pay any amount due beyond 15 days.
(b) The Customer engages in fraudulent, illegal, or unauthorised activities.
(c) The Customer’s use of the Platform poses a security risk or disrupts other users.
(d) Compliance with regulatory obligations requires suspension.
(e) The Provider must suspend services to comply with a court order or governmental request.
The Provider will notify the Customer of any suspension and will work in good faith to restore services upon resolution of the issue.
Upon termination of this Agreement, all rights and obligations under this Agreement shall cease, except for:
Upon termination or expiration of this Agreement, the Provider shall handle Customer Materials and Personal Data in accordance with the Data Processing Agreement, including applicable provisions relating to:
(a) retention periods;
(b) return or export of Customer Materials;
(c) deletion or anonymisation procedures;
(d) legal, regulatory, audit, backup, disaster recovery, and security retention obligations; and
(e) applicable post-termination access rights.
In the event of any conflict between this Agreement and the Data Processing Agreement regarding Personal Data processing, retention, deletion, export, or return obligations, the Data Processing Agreement shall prevail.
Subject to payment of applicable Fees and the Customer’s compliance with this Agreement, the Provider may provide reasonable post-termination assistance for a period of up to ninety (90) days following the effective date of termination or expiration of this Agreement (“Transition Period”).
During the Transition Period, the Customer may submit written requests for:
(a) export of Customer Materials held within the production environment of the Platform in a commonly used machine-readable format reasonably determined by the Provider, which may include CSV, JSON, XLSX, PDF, or other standard industry formats;
(b) reasonable transition and migration assistance relating to the transfer of Customer Materials to another service provider or internal system; and
(c) administrative cooperation reasonably required to support orderly service transition activities.
Unless otherwise expressly agreed in writing:
(i) post-termination assistance, migration services, restoration work, custom export formatting, technical consultancy, and related services shall be charged at the Provider’s then-current professional services rates;
(ii) the Provider is not responsible for:
(i) the Customer remains solely responsible for:
(i) archived backups, disaster recovery systems, security backups, logs, telemetry, and residual retained data may not be immediately accessible, searchable, or exportable during the Transition Period and shall continue to be governed by the Data Processing Agreement and applicable retention policies;
(ii) following expiration of the Transition Period, the Provider may delete or anonymise Customer Materials in accordance with this Agreement, the Data Processing Agreement, applicable law, and the Provider’s standard retention procedures.
Nothing in this Clause obliges the Provider to retain Customer Materials beyond applicable retention periods or to provide bespoke transition services unless separately agreed in writing.
Where Services are suspended or terminated due to non-payment, the Provider may restrict access to the Platform, Customer Materials, support services, and export functionality until all undisputed overdue amounts and applicable restoration or recovery Fees are paid.
The Provider shall continue to protect retained Customer Materials in accordance with the Data Processing Agreement and applicable law during any applicable retention period.
Any notice or communication given under this Agreement must be in writing and may be delivered:
(a) personally;
(b) by recognised courier or recorded delivery service;
(c) by email to the designated notice email address of the receiving party; or
(d) by electronic notification through the Platform for operational, service, support, renewal, billing, policy, security, or administrative notices.
Notices relating to termination, non-renewal, material breach, suspension, indemnity claims, changes to Fees, legal disputes, or other legal matters may validly be delivered by email.
Unless otherwise updated in writing, notices shall be sent to:
The Provider
Nicholas Jordan (Director)
Nuworks Ltd
Suite 5, 26-27 West Street
Horsham, West Sussex, RH12 1PB
Email: [email protected]
The Customer
As per details on the Order Form (Order Form)
A notice shall be deemed received:
(a) if delivered personally, at the time of delivery;
(b) if sent by courier or recorded delivery service, two (2) Business Days after dispatch;
(c) if sent by email, at the time of transmission, provided that the sending party does not receive an automated delivery failure or bounce notification within a reasonable period after transmission; and
(d) if delivered through the Platform, at the time the notice is made available to the Customer’s designated administrative account or notification centre.
Where deemed receipt would occur outside Business Hours, receipt shall instead occur at the start of the next Business Day.
15.6 Application to Data Processing Agreement
Unless otherwise expressly stated in the Data Processing Agreement, all notices, communications, approvals, objections, requests, and other correspondence relating to the Data Processing Agreement shall be governed by this Clause 15.
A "Force Majeure Event" means any event or circumstance beyond a party’s reasonable control, including, but not limited to:
(a) Acts of God, natural disasters (such as earthquakes, floods, hurricanes, and wildfires), and extreme weather conditions;
(b) Acts of war, hostilities, terrorism, civil unrest, riots, strikes, industrial disputes, or government-imposed lockdowns;
(c) Failures, outages, or disruptions of the internet, telecommunications, power, or utility services that are beyond the reasonable control of the affected party;
(d) Cyberattacks, ransomware attacks, or malicious third-party cybersecurity incidents beyond the reasonable control of the affected party;
(e) Compliance with any law, government order, regulation, embargo, or trade restriction;
(f) Pandemics, epidemics, or other public health crises that prevent the party from fulfilling its obligations.
A party that is affected by a Force Majeure Event shall:
(a) Notify the other party as soon as reasonably practicable, specifying the nature and expected duration of the event; and
(b) Use commercially reasonable efforts to mitigate the impact of the Force Majeure Event and resume performance of its obligations as soon as reasonably possible.
In the event of any dispute, controversy, or claim arising out of or relating to this Agreement (including its formation, validity, performance, or termination), the parties shall first attempt in good faith to resolve the dispute through negotiations between authorised representatives of each party.
Unless prohibited by law or where termination rights are exercised in accordance with this Agreement, each party shall continue to perform its obligations under this Agreement while any dispute is being resolved.
(a) This Agreement, including any referenced schedules, exhibits, policies, or addenda, constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior agreements, understandings, or arrangements (whether written or oral) relating to the same subject matter.
(b) Neither party shall be entitled to rely on any statement, representation, warranty, or understanding other than as expressly set out in this Agreement.
This Agreement and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it, its subject matter, or formation shall be governed by and construed in accordance with the laws of England and Wales.
The parties irrevocably agree that the courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Agreement.
Nothing in this Agreement shall prevent either party from seeking:
(a) The Provider may update or modify the following documents from time to time:
(i) the Acceptable Use Policy (AUP);
(ii) Schedule 1 (Service Level Schedule);
(iii) the Privacy Policy;
(iv) operational policies, privacy controls, Tracking Technologies controls, cookie governance requirements, security requirements, support procedures, or technical documentation incorporated into this Agreement; and
(v) any Supplemental Terms applicable to optional features or third-party integrations,
provided that such changes are reasonably necessary for:
(A) compliance with applicable law, regulation, or security requirements;
(B) reflecting changes to the Platform, Services, or business operations;
(C) improving security, functionality, or customer experience; or
(D) preventing misuse, fraud, or operational risk.
(b) The Provider shall provide the Customer with at least thirty (30) days’ prior notice of any material changes to the documents listed in Clause 18.7(a), including by email, electronic notification within the Platform, or publication on the Provider’s website.
(c) Non-material changes, including administrative corrections, clarifications, formatting updates, or changes required by law, may take effect immediately upon notice.
(d) If a change under this Clause 18.7 materially and disproportionately adversely affects the Customer’s use of the Services, and such change is not reasonably required for legal, regulatory, security, operational, technical, infrastructure, third-party dependency, or service improvement purposes, the Customer may elect not to renew the affected Services by providing written notice to the Provider before the commencement of the next renewal term.
(a) A non-renewal under Clause 18.7(d):
(i) shall take effect at the end of the then-current Subscription Term;
(ii) shall not affect the validity or enforceability of the revised terms during the current or renewed Subscription Term;
(iii) shall not relieve the Customer of payment obligations accrued prior to termination; and
(iv) shall be the Customer’s sole and exclusive remedy in respect of such change.
(a) Continued access to or use of the Services after the effective date of a notified change constitutes acceptance of the revised documents.
(b) For the avoidance of doubt, material amendments to the Data Processing Agreement affecting:
(i) the allocation of liability;
(ii) data protection roles;
(iii) lawful processing obligations; or
(iv) international data transfer mechanisms,
shall require mutual written agreement between the parties unless such amendment is required by applicable law, regulatory guidance, court order, or a mandatory update to recognised transfer mechanisms including Standard Contractual Clauses or equivalent approved transfer mechanisms.
Except as expressly permitted under Clause 18.7 (Changes to Incorporated Policies and Service Documents), no modification, amendment, or waiver of any provision of this Agreement shall be effective unless in writing and signed by duly authorised representatives of both parties.
18.10 Electronic Acceptance and Contract Formation
By accessing, registering for, purchasing, electronically accepting, signing, installing, or using the Platform or Services, the Customer acknowledges and agrees that:
(a) electronic acceptance of this Agreement, including by click-through acceptance, electronic signature, account registration, execution through an approved e-signature platform, or continued use of the Services, constitutes valid and legally binding acceptance of this Agreement;
(b) the individual accepting this Agreement represents and warrants that they have the authority to bind the Customer and any relevant legal entity on whose behalf access to the Services is obtained;
(c) electronic records maintained by the Provider relating to acceptance of this Agreement, including timestamps, account credentials, acceptance logs, version records, IP addresses, user identifiers, device information, audit logs, and related electronic evidence, shall be admissible in evidence to the fullest extent permitted by applicable law and shall constitute prima facie evidence of execution, acceptance, and use of the Services; and
(d) the parties agree that this Agreement and any related notices, consents, approvals, records, or communications may be executed, delivered, retained, and evidenced electronically.
(a) The Platform and related services;
(b) Customer-specific platform usage; and
(c) Customer Data stored within the Platform.
(a) Customer-side network or device failures;
(b) Third-party software or integrations; or
(c) Unapproved modifications made by the Customer.
The Provider will use commercially reasonable efforts to maintain monthly Platform availability of 99.5%, excluding:
Availability targets are service objectives only and do not constitute warranties, guarantees, service level commitments, or remedies.
The Provider shall maintain commercially reasonable backup procedures designed to support the availability and restoration of Customer Data stored within the production environment of the Platform.
Backup procedures are operational resilience measures and do not constitute a guarantee that all Customer Data, historical versions, metadata, configurations, integrations, logs, telemetry, or system states will be recoverable.
Unless otherwise agreed in writing:
The Provider does not guarantee uninterrupted availability, zero data loss, recovery of all historical data versions, or restoration to any specific point in time.
The Customer may request restoration of Customer Data where data loss, corruption, deletion, or operational recovery circumstances reasonably require restoration activities.
The Provider shall use commercially reasonable efforts to restore the most recent reasonably available backup copy determined by the Provider to be operationally recoverable.
Restoration activities:
Unless restoration is required solely due to the Provider’s breach of this Agreement or applicable Data Protection Laws, the Provider may charge reasonable Fees for:
Any recovery objectives, recovery time estimates, restoration priorities, backup frequency statements, retention statements, operational resilience targets, or disaster recovery targets communicated by the Provider are objectives only and do not constitute binding warranties, guarantees, service level commitments, RTOs, RPOs, or remedies.
The Provider does not provide binding Recovery Time Objective (RTO), Recovery Point Objective (RPO), disaster recovery testing, backup retention, or restoration commitments unless expressly stated in a separate written agreement signed by the Provider.
Archived backups, disaster recovery copies, system redundancy environments, logs, telemetry, and residual retained data may continue to exist for operational, legal, regulatory, security, audit, resilience, backup, archive, or disaster recovery purposes following deletion requests or termination of the Agreement, subject to the Data Processing Agreement and applicable retention policies.
The Customer must:
(a) Amendments to Customer-specific Platform use requirements (as set out in the Order Form);
(b) Modifications to Customer Materials;
(c) Enhancements or modifications to the Platform (excluding general Upgrades or New Functionality);
(d) Modifications to the sandbox environment.
The following are not considered Additional Projects under this Schedule:
(a) Modifications or enhancements classified as standard, as defined by the Provider;
(b) Routine updates, bug fixes, and maintenance performed as part of the Provider’s general service commitments;
(c) Services already included within the Customer’s existing licence agreement unless otherwise agreed as New Functionality;
(d) Any requests that fall outside the technical or operational scope of the Platform, as reasonably determined by the Provider.
(a) Completion of Scoping, or
(b) Issuance of an invoice—whichever is later (unless otherwise agreed in writing).
(a) The Provider confirming completion and making the Project Work available to the Customer in the live Platform or sandbox, or
(b) Issuance of the appropriate invoice—whichever is later (unless otherwise agreed in writing).
Requests for Additional Projects shall be submitted using a method determined by the Provider from time to time, which may include an online form, customer portal, email, ticketing system, or other agreed process.
The request process will typically capture, where applicable:
The Provider may amend or update the request process and the information required from time to time, provided such changes do not materially reduce the Customer's rights under this Agreement.